Don't kill Splunk. The splunk stop command tells Splunk to shut down gracefully. It waits for outstanding searches to complete before stopping. If you pull the rug out from under splunkd you risk corrupting your data in the event a lookup file is being written or a bucket is being updated.
--- If this reply helps you, Karma would be appreciated.